2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7581 | CRITICAL | 9.8 | 1.4% | Aug 7, 2024 | A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasic... |
| CVE-2024-7580 | CRITICAL | 9.8 | 8.9% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by thi... |
| CVE-2024-42005 | HIGH | 7.3 | 1.2% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on... |
| CVE-2024-41991 | HIGH | 7.5 | 1.0% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a... |
| CVE-2024-41990 | HIGH | 7.5 | 1.3% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filter... |
| CVE-2024-41989 | HIGH | 7.5 | 1.2% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to ... |
| CVE-2024-7579 | HIGH | 8.8 | 8.4% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by ... |
| CVE-2024-43199 | HIGH | 7.8 | 1.1% | Aug 7, 2024 | Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned ... |
| CVE-2024-43045 | MEDIUM | 6.3 | 4.3% | Aug 7, 2024 | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing att... |
| CVE-2024-43044 | HIGH | 8.8 | 28.8% | Aug 7, 2024 | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins contr... |
| CVE-2024-7578 | CRITICAL | 9.8 | 0.8% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected i... |
| CVE-2024-7355 | MEDIUM | 5.4 | 0.3% | Aug 7, 2024 | The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node... |
| CVE-2024-7353 | MEDIUM | 5.4 | 0.3% | Aug 7, 2024 | The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_str... |
| CVE-2024-7267 | MEDIUM | 6.5 | 0.6% | Aug 7, 2024 | Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy E... |
| CVE-2024-7266 | MEDIUM | 4.3 | 0.3% | Aug 7, 2024 | Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al... |
| CVE-2024-7265 | HIGH | 8.8 | 0.5% | Aug 7, 2024 | Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al... |
| CVE-2024-6522 | CRITICAL | 9.6 | 0.4% | Aug 7, 2024 | The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2024-7553 | HIGH | 7.8 | 0.3% | Aug 7, 2024 | Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl... |
| CVE-2024-5290 | HIGH | 7.8 | 0.7% | Aug 7, 2024 | An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a lo... |
| CVE-2024-42222 | MEDIUM | 4.3 | 1.0% | Aug 7, 2024 | In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network detail... |
| CVE-2024-42062 | HIGH | 7.2 | 0.9% | Aug 7, 2024 | CloudStack account-users by default use username and password based authentication for API and UI access. Account-users ... |
| CVE-2024-6494 | MEDIUM | 6.1 | 0.3% | Aug 7, 2024 | The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which... |
| CVE-2024-3973 | MEDIUM | 4.8 | 0.3% | Aug 7, 2024 | The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-37403 | MEDIUM | 5.5 | 0.5% | Aug 7, 2024 | Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to pr... |
| CVE-2024-36132 | HIGH | 7.5 | 1.2% | Aug 7, 2024 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now